Information Security Manager

Cypress Creek Renewables

Durham (OR)

Hybrid

USD 140,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

15 days of Paid Time Off
401(k) Match
Comprehensive health insurance package
Wellness stipend
Tuition Reimbursement
Phone Bill Reimbursement
Company Swag

Job summary

Cypress Creek Renewables is seeking an Information Security Manager in Durham, OR, to lead the company's security operations and compliance program. The successful candidate will enhance the security program and manage NIST-based compliance initiatives.

This hands-on position offers opportunities for significant contribution to evolving policies, particularly with artificial intelligence, while working closely with IT and other stakeholders.

Competitive salary range of $140,000 - $170,000, with comprehensive benefits included.

Qualifications

  • Use of AI to enhance and scale security operations.
  • 5+ years of experience in information security.
  • Strong SIEM experience and vulnerability management.

Responsibilities

  • Administer and tune Microsoft Defender across endpoints.
  • Manage Zscaler platform for access controls and policy development.
  • Own SIEM tuning and alert incident workflows.
  • Run vulnerability scanning program across AWS and Azure.
  • Lead investigations into security events and perform forensic analysis.

Skills

AI utilization in security operations
Microsoft Defender administration
Zscaler management
SIEM operations
Vulnerability management
Digital forensics
NIST Cybersecurity Framework
Risk management
Communication skills

Education

Bachelor's degree in computer science, information systems, or cybersecurity

Tools

Microsoft Defender
Zscaler (ZIA/ZPA)
SIEM tools

Job description

The Company

Cypress Creek Energy is powering a sustainable future, one project at a time. We develop, finance, own and operate utility-scale and distributed solar and storage projects across the country. Fostering a diverse group of innovative thinkers from all backgrounds, Cypress people are drawn to work in a purpose-driven organization. We hope you will join us.

Overview

Cypress Creek Energy is hiring an Information Security Manager to lead the company's security operations and compliance program. This is a hands‑on individual contributor role designed for a senior technical security professional ready to take ownership of a complete program — with the opportunity to grow into a leader of a team as the function scales.

The successful candidate brings a balance of deep technical execution and program‑level compliance maturity. You will own the day‑to‑day security tooling stack, lead the company's NIST-based compliance program, shape policy in emerging areas including artificial intelligence, and maintain an accurate view of every system in the environment. You will report directly to the Chief Technology Officer and partner closely with IT, Counsels, and business stakeholders across the company.

Responsibilities
Security Operations & Engineering
  • Endpoint security: Administer and tune Microsoft Defender across the endpoint estate, including policy configuration, alert triage, response, and reporting.
  • Network and access security: Manage the Zscaler platform (ZIA/ZPA), including policy development, traffic inspection, access controls, and integration with identity systems.
  • SIEM operations: Own SIEM tuning, detection engineering, log source onboarding, alerting, and incident workflows. Build dashboards and metrics that surface meaningful signals.
  • Vulnerability management: Run the vulnerability scanning program across AWS and Azure cloud environments and on‑premises infrastructure. Prioritize, track, and verify remediation in partnership with IT and engineering teams.
  • Patch management: Maintain endpoint patching cadence and reporting, ensuring coverage, exception tracking, and SLA adherence.
  • Digital forensics & incident response: Lead investigations into security events, perform forensic analysis, document findings, and coordinate response with internal teams and external partners as needed.
Compliance & Governance
  • NIST-based program: Maintain and continuously improve the company's NIST Cybersecurity Framework‑aligned security program, including controls mapping, evidence collection, and gap remediation.
  • Policy management: Own the security policy library — ensure policies and standards are current, reviewed on a defined cadence, approved through the right channels, and communicated to the business.
  • AI policy and guidance: Develop and maintain the company's AI usage policies, acceptable use guidance, and review process for new AI tools, in coordination with Counsels and IT.
  • System inventory: Build and maintain an authoritative inventory of systems, applications, data flows, and ownership. Keep it accurate as the environment evolves.
  • Audit and assessment support: Lead responses to internal and external audits, customer security reviews, and regulatory inquiries. Manage remediation of identified findings through closure.
  • Risk management: Identify, document, and track information security risks; propose mitigations and report on residual risk to leadership.
Leadership & Cross-Functional Partnership
  • Stakeholder engagement: Partner with IT, Counsels, HR, and business leaders on security matters, providing clear guidance that balances risk with business needs.
  • Operational Technology (OT): Act as a partner and advisor to the OT team coordinating security and compliance initiatives across the company. Manage intersection of IT and OT endpoints, systems, and networks.
  • Security awareness: Drive the security awareness program, including phishing simulations, training content, and ongoing communications.
  • Vendor and third‑party risk: Assess and manage security risk associated with vendors, contractors, and third‑party service providers.
  • Future team leadership: Lay the groundwork to scale the function. As the program matures, hire, mentor, and lead a team of security professionals.
Education & Experience Required
  • Use of AI to enhance and scale security operations – establish AI first Security Ops
  • Bachelor's degree in computer science, information systems, cybersecurity, or related field — or equivalent professional experience.
  • 5+ years of progressive experience in information security, with demonstrated depth in security operations, engineering, or a combination of both.
  • Hands‑on administration and tuning experience with Microsoft Defender (Endpoint, Identity, Cloud).
  • Production experience operating Zscaler (ZIA and/or ZPA), including policy management and troubleshooting.
  • Strong SIEM experience — building detections, tuning alerts, investigating incidents, and onboarding log sources.
  • Vulnerability management experience across cloud environments, specifically AWS and Azure.
  • Working knowledge of digital forensics and incident response methodology.
  • Demonstrated experience operating a security program aligned to the NIST Cybersecurity Framework or NIST 800‑53.
  • Track record of writing, maintaining, and operationalizing security policies and standards.
  • Clear written and verbal communication, including the ability to explain technical risk to non‑technical audiences.
  • Ability to work from the Durham, NC or Washington, DC office three days per week.
  • Embrace and live by the mission and values of Cypress Creek Energy
Preferred Qualifications
  • Industry certifications such as CISSP, CISM, GIAC (GCIH, GCFA, GCIA), or equivalent.
  • Experience operating in the energy, utility, or critical infrastructure sector.
  • Familiarity with NERC CIP or other regulatory frameworks relevant to the power sector.
  • Experience scripting or automating security workflows (Python, PowerShell, KQL).
  • Prior experience as a senior technical lead preparing to step into a manager role.
Location

The preferred location for this role is for our offices in Durham, NC and Washington, DC. Our team operates on a hybrid schedule, with in‑office schedule of three days per week.

Compensation

The salary range for the position is $140,000 - $170,000 plus bonus and benefits. Compensation may vary outside of this range depending on a number of factors, including a candidate’s qualifications, skills, competencies and experience, and location.

Benefits
  • 15 days of Paid Time Off, accrual up to 20 days, 11 observed holidays.
  • 401(k) Match
  • Comprehensive package including medical, dental, vision and health insurance
  • Wellness stipend, family planning stipend, and generous parental leave
  • Tuition Reimbursement
  • Phone Bill Reimbursement
  • Company Swag
Equal Opportunity Employer

Cypress Creek Energy is an equal opportunity employer and considers all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or veteran status. We are committed to providing a workplace that is inclusive and values diversity, and we encourage candidates from all backgrounds to apply.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Manager
Information Security Manager

Cypress Creek Energy • Washington

Hybrid
USD 140,000 - 170,000
15 days of Paid Time Off
401(k) Match
Medical, dental, and vision insurance
+2
Community Affairs Leader
Community Affairs Leader

Cypress Creek Energy • United States

Hybrid
USD 120,000 - 150,000
PTO 15 days
Accrual up to 20 days PTO
Holidays 11
+6
Senior Director, Development
Senior Director, Development

Cypress Creek Energy • Chicago (IL)

Hybrid
USD 200,000 - 235,000
PTO 15 days
401(k) match
Medical, dental, vision
+4
Sr. Director, Site Acquisition
Sr. Director, Site Acquisition

Cypress Creek Renewables • Asheville (NC), Durham (NC), Chicago (IL), San Francisco (CA)

Hybrid
USD 216,000 - 264,000
PTO 15 days + holidays
401(k) match
Medical/dental/vision
+6
Senior Manager/Associate Director, Environmental Affairs
Senior Manager/Associate Director, Environmental Affairs

Cypress Creek Energy • Durham (NC)

Hybrid
USD 100,000 - 145,000
PTO 15 days
401(k) match
Wellness stipend
+3
Information Security Manager
Information Security Manager

Ecotal • Durham (NC)

Hybrid
USD 120,000 - 180,000
Senior Information Security Lead — NIST & AI Policy
Senior Information Security Lead — NIST & AI Policy

Cypress Creek Energy • Washington

Hybrid
USD 140,000 - 170,000
15 days of Paid Time Off
401(k) Match
Medical, dental, and vision insurance
+2
Senior Analyst, Structured Finance
Senior Analyst, Structured Finance

Cypress Creek Renewables • San Francisco (CA)

Hybrid
USD 115,000 - 135,000
PTO & holidays
401(k) match
Health benefits
+4
Senior Operations Engineer
Senior Operations Engineer

Cypress Creek Renewables • New York (NY), Chicago (IL)

Hybrid
USD 100,000 - 135,000
15 days Paid Time Off
401(k) Match
Medical, dental, vision insurance
+4
Engineer, Cloud Security
Engineer, Cloud Security

Clean Power Alliance • United States

Hybrid
USD 159,000 - 238,000
Health care
401(k)-like match
Paid vacation
+1